Attack outcomes
Double extortion
Also called: data extortion
Double extortion is a ransomware tactic in which attackers both encrypt a victim's systems and steal a copy of its data, then demand payment for two things: the decryption key and a promise not to publish the stolen files. Even an organization that restores from backups still faces the threat of a leak.
How it works
After getting in, the attackers quietly copy sensitive files to their own servers before deploying ransomware. The ransom note points to a leak site where they list the victim and post samples. If the victim refuses to pay, they release the data or sell it.
A real example
The FBI, CISA, HHS and MS-ISAC's Black Basta advisory said affiliates used common initial access techniques such as phishing and then employed a double-extortion model, both encrypting systems and exfiltrating data.
Source: #StopRansomware: Black Basta (AA24-131A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-05-10
How to stop it
Block the initial login with phishing-resistant MFA, limit how much data any one identity can read, and alert on large outbound transfers.
Related terms
Threat actors that use it
- Akira
Profile with government sources
- Black Basta
Profile with government sources
- LockBit
Profile with government sources
Sources
- #StopRansomware: Black Basta (AA24-131A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-05-10
Last reviewed Oct 2, 2026